AndroidPure
  • Leaks
  • News
  • Reviews
  • Updates
  • How to
No Result
View All Result
  • Leaks
  • News
  • Reviews
  • Updates
  • How to
No Result
View All Result
AndroidPure
No Result
View All Result

Android Ad SDKs Are Sharing Your Precise Location by Default, EFF Finds

Androidpure Staff by Androidpure Staff
August 8, 2026
in News

Four widely used advertising SDKs embedded in Android apps are silently collecting and sharing users’ precise location data with advertisers — and developers may not even realize it’s happening. A new report from the Electronic Frontier Foundation names InMobi, BidMachine, Verve/HyBid, and Huawei Petal Ads as ad libraries that default to harvesting location the moment a host app has location permission, with no additional user consent required.

The core problem is an architectural gap in Android’s permission model. As the EFF’s researchers put it: “Once a user grants an app permission to access their location, SDKs embedded in the app receive the same access — there are no SDK-specific location permissions.” That means when you allow a QR code scanner to use your GPS, every advertising library bundled inside that app gets your coordinates too — and you have no way to block one without blocking the other.

How Big Is the Reach?

The four SDKs collectively touch billions of devices. InMobi, the tenth most popular Android ad SDK, claims over 2 billion users across 150+ countries and tells developers that “location-enriched impressions typically yield higher revenue.” BidMachine reaches over 600 million direct SDK users. Verve/HyBid is embedded in more than 10,000 apps serving over 1.5 billion users, with location tracking enabled by default. Huawei’s Petal Ads sits inside more than 85,000 apps worldwide.

The EFF’s technical testing caught BidMachine transmitting precise GPS coordinates from two real apps — QR Scanner (50 million+ downloads) and GPS Speedometer (10 million+ downloads). Neither app disclosed third-party location sharing in its Google Play Store Data Safety section, meaning users had no way to know their location was being sold on through the advertising chain.

Google Play Data Safety section failing to disclose third-party location sharing by embedded ad SDKs
Image: EFF

Where Does the Location Data Go?

Ultimately, to data brokers — and from there, to buyers with deep pockets and few scruples. As TechCrunch’s Zack Whittaker reported, “the users’ location histories get fed to data brokers, who monetize that information, which then gets sold to militaries, governments, and intelligence agencies, like the FBI.” That is the real cost of a “free” app monetized through location-enriched advertising: your daily movements ending up in a government surveillance database, with no warrant and no notification.

What Can You Do?

Users have limited options. You can revoke location permission from apps that don’t genuinely need it — a QR scanner has no business knowing where you are. On Android 12 and later, you can grant “approximate” instead of “precise” location, which at least limits GPS-level tracking. But these are band-aids over a systemic problem: Android’s permission model was never designed to let users control what SDKs do inside an app they’ve already trusted.

The EFF’s recommendation is aimed squarely at developers: “Developers should carefully evaluate all third-party SDKs they include in their apps and disable unnecessary data collection whenever possible.” More broadly, the report calls on regulators to hold SDK companies accountable and on legislators to enact a federal location privacy law — and to consider banning online behavioral advertising entirely.

That last point is worth lingering on. The ad industry’s defense is always that location data is “anonymized” or “approximate.” Verve/HyBid told the EFF it only uses network-derived location rounded to about half a square mile. But as we’ve covered before, the gap between what companies say about privacy and what their code actually does is often wide — and the user is always the last to find out.

“Advertising SDKs should not make sharing personal data the default, especially for data as sensitive as a person’s location.”

Until Android gains SDK-level permission controls — letting users grant location to an app but deny it to the ad library inside — the only real protection is vigilance: audit your app permissions regularly, deny location access to anything that doesn’t need it, and assume that every “free” app is paying for itself with your data.

Sources: EFF, TechCrunch

Tags: ad sdkandroid privacyeffGoogle Playlocation tracking
ShareTweetSendShare
Previous Post

Samsung Quick Share Can Now Send Wallet Tickets and Boarding Passes to Other Galaxy Users

Androidpure Staff

Androidpure Staff

Androidpure Staff delivers the latest from the Android world — phone launches, software updates, and practical how-to guides — without the press-release fluff. We focus on what genuinely matters to readers, in India and around the globe.

Follow Us

  • 914 Followers

Popular

  • Motorola smartphone running Android 17 beta with new UI features

    Motorola Android 17 Beta Reveals Qira AI, Redesigned Live Updates, and an Unannounced Edge 70 Neo

    Share
    Share Tweet
  • POCO M8 Power 5G Launched in India: Price Starts at Rs 24,999 With 8,000mAh Battery

    Share
    Share Tweet
  • CMF Clip Pro Launched: Nothing’s First Open-Ear Earbuds Start at

    Share
    Share Tweet
  • JioTag 2 Launches in India at Rs 1,249 With Find Hub and Find My

    Share
    Share Tweet
  • vivo S2 Launches in India After Seven-Year S Series Hiatus: Pricing, Specs, Availability

    Share
    Share Tweet
  • Redmi K100 Pro Max Shows Up With a 9,070mAh Battery Before Launch

    Share
    Share Tweet
  • Galaxy F70 Pro 5G Lands in India August 3, Samsung Confirms Specs

    Share
    Share Tweet

Latest

Google Play Data Safety section showing location data not shared with third parties despite ad SDK location collection

Android Ad SDKs Are Sharing Your Precise Location by Default, EFF Finds

August 8, 2026
Samsung logo

Samsung Quick Share Can Now Send Wallet Tickets and Boarding Passes to Other Galaxy Users

August 8, 2026
Google Pixel Watch 5 teaser showing circular watch design

Pixel Watch 5 Teaser Takes a Shot at Apple and Samsung: ‘Decency to Look Like a Watch’

August 8, 2026
Redmi K100 Pro Max rear camera module with 200MP main sensor and 5x periscope telephoto

Redmi K100 Pro Max Reveals 200MP Camera System Ahead of August 11 Launch

August 7, 2026
Google Wallet icon logo

Google Wallet Now Lets Parents Send Money to Kids for Tap-to-Pay Purchases

August 7, 2026
Google logo representing the Made by Google 2026 Pixel 11 launch event

Made by Google 2026: Trevor Noah Hosts Pixel 11 Launch Event on August 12

August 7, 2026
GrapheneOS logo, the privacy-focused Android operating system

GrapheneOS Accuses Revolut of Blocking Users Over Google Play Licensing, Not Security

August 7, 2026
AndroidPure

© 2024 AndroidPure - NonStop Android.

Navigate Site

  • Privacy
  • About Us
  • Tip Us
  • Contact Us

Follow Us

No Result
View All Result
  • Leaks
  • News
  • Reviews
  • Updates
  • How to

© 2024 AndroidPure - NonStop Android.